Endpoint Protection

 View Only
  • 1.  How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 16, 2013 09:32 PM

     

    Hi Guys,

     

    My file server has been infected by w32.svich and it creates about hundreds of thousands of this foldername.exe file. How can I delete these files automatically and how can I prevent my server from this virus again? I already did this http://www.symantec.com/security_response/writeup.jsp?docid=2007-062911-2859-99&tabid=3 so please give a better one. My current version is SEP 11 without NTP.

     

     

    Regards,

    N



  • 2.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 16, 2013 09:35 PM

    You need to find out how the infection is re-occuring.

    It sounds like a user may be connecting to the file share and re-infecting. Have you turned off autorun on the file server? This is highly recommended if you haven't. If you can't turn it off, try this workaround:

    How to prevent Autorun.inf files being copied or written to network file shares

    Article:TECH131807  |  Created: 2010-01-19  |  Updated: 2012-03-07  |  Article URL http://www.symantec.com/docs/TECH131807

    Are you running a full system scan?



  • 3.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 16, 2013 09:54 PM

    Hi Brian,

     

    Thanks for the response, I'll try this one. But do you have a tool removing the foldername.exe created by this virus? I know you are aware to this virus,are you?

    Thanks,



  • 4.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 17, 2013 01:10 AM

    Disable the autorun.inf

    Check your systems are updated with latest Defintion and micrsoft patches?

    Run full scan in safe mode.

    If continuously reflect that virus then submit the virus to symantec security team

    https://submit.symantec.com/essential

    https://www-secure.symantec.com/connect/forums/folder-getting-created-folderexe#comment-7428991

    https://www-secure.symantec.com/connect/forums/folderexe-virus-removal#comment-7559141



  • 5.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 17, 2013 08:34 AM

    Yes, I'm aware of it. There is no official removal tool. You would need to build/script one.



  • 6.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Trusted Advisor
    Posted Aug 19, 2013 06:13 AM

    Hello,

    Are you running all the latest Microsoft updates and security patches on the machine?

    I have seen W32.Changeup causing this behaviour. It hides folders on a network share or removable drive and creates a rogue executable with the same name, and also creates an autorun file. The virus has been around a while and SEP catches it, but there is a chance that a recently coded variant is not yet recognised by current definitions.

    Check this Article:

    W32.Changeup keeps on giving

    https://www-secure.symantec.com/connect/blogs/w32changeup-keeps-giving

    Plan of Action:

    1. Run a scan in safe mode with networking to remove the virus. (Make sure SEP is updated with the Latest definitions)
    2. Disable System Restore before you do this as the virus alse creates entries in the System Restore Points store volumes.
    3. Disable Autoplay for ALL DRIVES Via a GPO (If you're on a domain), and
    4. Disable SImple File Sharing if it's enabled to prevent the infection from propogating itself by binding to files.
    5. Secondly, Submit these files to the Symantec Security Response and they will get detected. https://submit.symantec.com/essential

    We also offer a self-service site to analyze files, at http://www.threatexpert.com, which can give you more information on the files you submit to it.

    Check this article:

    Using Symantec Help (SymHelp) Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.

    https://www-secure.symantec.com/connect/articles/using-symantec-help-symhelp-tool-how-do-we-collect-suspicious-files-and-submit-same-symante

    Hope that helps!!



  • 7.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 19, 2013 07:17 AM

    Follow this discussion , should resolve the issue

    https://www-secure.symantec.com/connect/forums/virus-issue-foldernameexe



  • 8.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 22, 2013 09:30 PM

     

    Hi Brian,

     

    I know its a shame to ask, but do you have the script? And may I have it and test it?

    Regards,

    N

     



  • 9.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 23, 2013 06:39 AM

    Have you tried the above comment?



  • 10.  RE: How to remove automatically the folder.exe files that created by w32.svich

    Posted Aug 23, 2013 06:43 AM